AP

Microsoft says early June disruptions to Outlook, cloud platform, were cyberattacks

Jun 19, 2023, 9:13 AM | Updated: 10:44 am

microsoft layoffs new year...

FILE - The Microsoft logo in the Mobile World Congress 2023 in Barcelona, Spain, on March 2, 2023. (AP Photo/Joan Mateu Parra, File)
Credit: ASSOCIATED PRESS

(AP Photo/Joan Mateu Parra, File)

In early June, sporadic but serious service disruptions plagued Microsoft’s flagship office suite — including the Outlook email and OneDrive file-sharing apps — and cloud computing platform. A shadowy hacktivist group claimed responsibility, saying it flooded the sites with junk traffic in distributed denial-of-service attacks.

Initially reticent to name the cause, Microsoft has now disclosed that DDoS attacks by the murky upstart were indeed to blame.

But the software giant has offered few details — and did not immediately comment on how many customers were affected and whether the impact was global. A spokeswoman confirmed that the group that calls itself Anonymous Sudan was behind the attacks. It claimed responsibility on its Telegram social media channel at the time. Some security researchers believe the group to be Russian.

Microsoft’s explanation in a blog post Friday evening followed a request by The Associated Press two days earlier. Slim on details, the post said the attacks “temporarily impacted availability” of some services. It said the attackers were focused on “disruption and publicity” and likely used rented cloud infrastructure and virtual private networks to bombard Microsoft servers from so-called botnets of zombie computers around the globe.

Microsoft said there was no evidence any customer data was accessed or compromised.

While DDoS attacks are mainly a nuisance — making websites unreachable without penetrating them — security experts say they can disrupt the work of millions if they successfully interrupt the services of a software service giant like Microsoft on which so much global commerce depends.

It’s not clear if that’s what happened here.

“We really have no way to measure the impact if Microsoft doesn’t provide that info,” said Jake Williams, a prominent cybersecurity researcher and a former National Security Agency offensive hacker. Williams said he was not aware of Outlook previously being attacked at this scale.

“We know some resources were inaccessible for some, but not others. This often happens with DDoS of globally distributed systems,” Williams added. He said Microsoft’s apparent unwillingness to provide an objective measure of customer impact “probably speaks to the magnitude.”

Microsoft dubbed the attackers Storm-1359, using a designator it assigns to groups whose affiliation it has not yet established. Cybersecurity sleuthing tends to take time — and even then can be a challenge if the adversary is skilled.

Pro-Russian hacking groups including Killnet — which the cybersecurity firm Mandiant says is Kremlin-affiliated — have been bombarding government and other websites of Ukraine’s allies with DDoS attacks. In October, some U.S. airport sites were hit. Analyst Alexander Leslie of the cybersecurity firm Recorded Future said it’s unlikely Anonymous Sudan is located as it claims in Sudan, an African country. The group works closely with Killnet and other pro-Kremlin groups to spread pro-Russian propaganda and disinformation, he said.

Edward Amoroso, NYU professor and CEO of TAG Cyber, said the Microsoft incident highlights how DDoS attacks remain “a significant risk that we all just agree to avoid talking about. It’s not controversial to call this an unsolved problem.”

He said Microsoft’s difficulties fending of this particular attack suggest “a single point of failure.” The best defense against these attacks is to distribute a service massively, on a content distribution network for example.

Indeed, the techniques the attackers used are not old, said U.K. security researcher Kevin Beaumont. “One dates back to 2009,” he said.

Serious impacts from the Microsoft 365 office suite interruptions were reported on Monday June 5, peaking at 18,000 outage and problem reports on the tracker Downdetector shortly after 11 a.m. Eastern time.

On Twitter that day, Microsoft said Outlook, Microsoft Teams, SharePoint Online and OneDrive for Business were affected.

Attacks continued through the week, with Microsoft confirming on June 9 that its Azure cloud computing platform had been affected.

On June 8, the computer security news site BleepingComputer.com reported that cloud-based OneDrive file-hosting was down globally for a time.

Microsoft said at the time that desktop OneDrive clients were not affected, BleepingComputer reported.

AP

Seattle non-profits...

Associated Press

Oregon man convicted of murder in fatal shooting of sheriff’s deputy in Washington state

A jury has convicted an Oregon man of murder in the fatal shooting of a sheriff’s deputy in Washington state.

10 hours ago

Image: Former U.S. President Donald Trump speaks to a crowd during a campaign rally on Monday, Sept...

Associated Press

Judge rules Donald Trump defrauded banks, insurers while building real estate empire

A judge ruled Tuesday that Donald Trump committed fraud for years while building the real estate empire that catapulted him to fame and the White House.

1 day ago

FILE - The Amazon logo is displayed, Sept. 6, 2012, in Santa Monica, Calif. Amazon's profitable clo...

Haleluya Hadero, Associated Press

Amazon sued by FTC and 17 states over allegations it inflates online prices and overcharges sellers

The FTC filed an antitrust lawsuit against Amazon on Tuesday, alleging the e-commerce behemoth uses its position in the marketplace to inflate prices

1 day ago

KYIV, UKRAINE - 2022/09/03: A man looks at an image generated based on the stories of displaced chi...

Associated Press

Tech companies try to take AI image generators mainstream with better protections against misuse

Artificial intelligence tools that can conjure whimsical artwork or realistic-looking images from written commands started wowing the public last year. But most people don't actually use them at work or home.

1 day ago

Image: Actor David McCallum attends an event for "NCIS" during the 2009 Monte Carlo Television Fest...

Associated Press

David McCallum, star of hit series ‘The Man From U.N.C.L.E.’ and ‘NCIS,’ dies at 90

Actor David McCallum, who was the eccentric medical examiner in the popular "NCIS," has died. He was 90.

2 days ago

FILE - COVID-19 antigen home tests indicating a positive result are photographed in New York, April...

Associated Press

Biden administration announces $600M to produce and distribute COVID tests

The Biden administration announced Wednesday that it is providing $600 million in funding to produce new at-home COVID-19 tests and is restarting a website allowing Americans to again order up to four free tests per household

2 days ago

Sponsored Articles

Swedish Cyberknife...

September is Prostate Cancer Awareness Month

September is a busy month on the sports calendar and also holds a very special designation: Prostate Cancer Awareness Month.

Ziply Fiber...

Dan Miller

The truth about Gigs, Gs and other internet marketing jargon

If you’re confused by internet technologies and marketing jargon, you’re not alone. Here's how you can make an informed decision.

Education families...

Education that meets the needs of students, families

Washington Virtual Academies (WAVA) is a program of Omak School District that is a full-time online public school for students in grades K-12.

Emergency preparedness...

Emergency planning for the worst-case scenario

What would you do if you woke up in the middle of the night and heard an intruder in your kitchen? West Coast Armory North can help.

Innovative Education...

The Power of an Innovative Education

Parents and students in Washington state have the power to reimagine the K-12 educational experience through Insight School of Washington.

Medicare fraud...

If you’re on Medicare, you can help stop fraud!

Fraud costs Medicare an estimated $60 billion each year and ultimately raises the cost of health care for everyone.

Microsoft says early June disruptions to Outlook, cloud platform, were cyberattacks